Fork CMS contains a SQL injection vulnerability in versions prior to version 5.11.1. When deleting submissions which belong to a formular (made with module FormBuilder
), the parameter id[]
is vulnerable to SQL injection.
{ "nvd_published_at": "2022-03-24T17:15:00Z", "github_reviewed_at": "2022-03-29T20:36:57Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-89" ] }